CVE-2021-46880
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-46880 affects LibreSSL before version 3.4.2 and OpenBSD before version 7.0 errata 006. The vulnerability exists in the x509/x509_verify.c component, where an authentication bypass could occur because an error for an unverified certificate chain is sometimes discarded (CVE Details, NVD).

Technical details

The vulnerability is present in the x509/x509_verify.c component of LibreSSL and OpenBSD. The issue occurs when the verification callback is in use, instructing the verifier to continue unconditionally, which could lead to incorrect security decisions being made. The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD, NetApp Advisory).

Impact

Successful exploitation of this vulnerability could lead to authentication bypass, potentially resulting in disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). The critical CVSS score indicates the severe nature of this security flaw (NetApp Advisory).

Mitigation and workarounds

The vulnerability has been fixed in LibreSSL version 3.4.2 and OpenBSD 7.0 errata 006. Users should upgrade to these versions or later to address the security issue. The fix involves correcting how the x509 verifier handles errors during certificate chain verification (LibreSSL Release Notes, OpenBSD Patch).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69264CRITICAL9.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69263HIGH8.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69262HIGH7.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-20807MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2026-21885MEDIUM6.5
  • NixOSNixOS
  • miniflux
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management